AI export controls in 2026: what they mean for enterprise model choice

How 2026 US export controls and the EU AI Act reshape which AI models and chips enterprises can legally deploy.

Read time
14 min
Word count
2.4K
Sections
10
FAQs
8
Share
Corporate compliance workspace with digital regulatory dashboards and global network visualization
2026 model selection now hinges on chips, geography, and regulatory compliance—not just benchmarks.
On this page · 10 sections
  1. What actually changed in US export controls, 2025 to 2026
  2. The enforcement reality is the part that bites
  3. Why this lands on model choice, not just chip procurement
  4. The China open-weight question, with numbers
  5. The EU AI Act timeline collides with the 2026 buying cycle
  6. A model-selection process that survives an audit
  7. India-specific considerations
  8. How eCorpIT can help
  9. FAQ
  10. References

Summary. On 13 May 2025 the US Bureau of Industry and Security (BIS) rescinded the Biden-era AI Diffusion Rule two days before it was due to take effect, then on 13 January 2026 issued a final rule moving NVIDIA H200- and AMD MI325X-equivalent chip exports to China and Macau from "presumption of denial" to case-by-case review. In February 2026 BIS settled with Applied Materials for $252 million, its second-largest standalone penalty. The EU AI Act becomes broadly applicable on 2 August 2026, with fines up to €35 million or 7% of worldwide turnover. Chinese open-weight models went from roughly 1% to roughly 30% of tokens routed through OpenRouter, the largest neutral LLM router (a developer-traffic indicator, not global usage — first-party ChatGPT/Gemini traffic is far larger), with weekly peaks near 46% by mid-2026. For a CTO, the model-selection question is now partly a legal one: which weights, which chips, and which cloud you can run without aiding an Export Administration Regulations (EAR) violation.

The decision used to be a benchmark exercise. You ran your evals, compared latency and cost per million tokens, and picked the model that scored best. In 2026 that is no longer enough. The chip your inference runs on, the country your data centre sits in, the parent company of your model vendor, and the jurisdiction of your users all now carry regulatory weight. A wrong call does not just cost accuracy. It can put your organisation inside the EAR's "knowledge" standard or on the wrong side of an EU conformity assessment.

This guide is for CTOs, AI strategy leads, and compliance teams who have to choose models for production in this environment. It covers what changed in US export policy between January 2025 and 2026, how the EU AI Act timeline interacts with model choice, where China's open-weight models fit, and what Indian enterprises operating under the Digital Personal Data Protection Act 2023 (DPDP) should weigh. The goal is a defensible model-selection process, not a politics lecture.

What actually changed in US export controls, 2025 to 2026

The Biden administration published the Framework for Artificial Intelligence Diffusion as an interim final rule on 15 January 2025. It created a tiered, worldwide licensing regime for advanced computing integrated circuits and a new export classification, ECCN 4E091, for the model weights of the most advanced AI models. The rule sorted countries into three tiers, with per-country compute caps and a new authorisation process for building data centres abroad.

It never took effect. BIS announced on 13 May 2025 that it would rescind the rule, two days before the 15 May compliance date. The agency said the rule was overly bureaucratic, would have stifled American innovation, and would have downgraded dozens of US partners to second-tier status. Under Secretary of Commerce for Industry and Security Jeffery Kessler directed enforcement officials to stop enforcing it. ECCN 4E091, the model-weights control, was effectively removed.

Rescission did not mean deregulation. On the same day, BIS issued three guidance documents and a policy statement covering the risks of using Chinese advanced computing chips, the consequences of letting US chips train Chinese models, and how to protect supply chains from diversion. These are not regulations, but they confer "knowledge" on industry that can itself trigger a licence requirement under the EAR's catch-all controls in Part 744.

Then the policy shifted again. On 8 December 2025 President Trump announced the US would permit some chip sales to approved customers in China. On 13 January 2026 BIS issued a final rule revising the licence review posture for NVIDIA H200- and AMD MI325X-equivalent chips and lesser-performance parts from presumption of denial to case-by-case review for exports from the United States to China and Macau (reexports and in-country transfers stay at presumption of denial), subject to technical, business, end-user, and US-market certifications. The next day, the President issued a proclamation adjusting semiconductor imports into the United States.

The through-line for an enterprise is this: the specific rules keep moving, but the EAR's underlying "knowledge" standard and Entity List have stayed in force the whole time. You are expected to know who your counterparties are.

The enforcement reality is the part that bites

Policy flexibility at the top has not loosened enforcement at the bottom. If anything, the opposite. Congress approved a 23% increase in BIS's Fiscal Year 2026 budget, with money marked specifically for semiconductor-related enforcement. The recent cases show how that capacity is being used.

In July 2025, DOJ and BIS resolved a case with Cadence Design Systems, which agreed to plead guilty and pay over $140 million for unlawfully exporting semiconductor design tools to a restricted Chinese military university; the violations occurred between 2015 and 2020. In February 2026, BIS announced a $252 million settlement with Applied Materials over the illegal export of semiconductor manufacturing equipment to a Chinese Entity List company through a South Korean subsidiary. Routing the technology through an intermediate subsidiary gave no defence, and compliance staff responsible for the shipments were terminated as a settlement condition. On 8 December 2025, DOJ's Operation Gatekeeper disrupted a network responsible for at least $160 million in AI chip exports to mainland China and Hong Kong.

The pattern across these cases is the use of third-country intermediaries and front companies to hide the final Chinese destination. That is the same diversion pathway BIS flagged in its May 2025 red-flag guidance. One more change to track: the BIS Affiliates Rule, which extends restrictions to majority-owned subsidiaries of listed entities, has its enforcement paused until late 2026, and forward-looking companies are mapping those ownership links now.

Craig Singleton, senior fellow at the Foundation for Defense of Democracies, put the strategic stakes plainly: the chips, tools, memory, and cloud infrastructure behind frontier AI are not just commercial goods, they're "really strategic assets." For a buyer, the takeaway is narrower: the government treats your inference cluster as a strategic asset whether or not you do.

Why this lands on model choice, not just chip procurement

Most CTOs do not buy H200s. They rent inference from a cloud provider or call a model API. So why does an export-control regime aimed at chips and weights change which model you pick?

Three reasons. First, the chip controls flow downstream. The January 2026 rule explicitly names cloud service providers and colocation data centres offering access to controlled compute, and multinationals deploying controlled chips across borders, as parties who should heed the new conditions. If your inference runs in a region served by controlled hardware, the provider's compliance posture becomes your dependency.

Second, vendor parentage matters. The EAR's "knowledge" standard and the Entity List operate on who owns and controls a counterparty, not just where a server sits. A model whose ultimate parent is headquartered in a Country Group D:5 destination, including China, carries a different risk profile from one that is not, regardless of how the weights are licensed.

Third, open weights cross borders by their digital nature. The rescinded 4E091 control applied only to the most advanced closed-weight models and expressly excluded published open-weight models — the gap it left is precisely why open weights move across borders without a shipping container. Even with that specific control gone, BIS guidance warns infrastructure-as-a-service providers about training models on behalf of D:5-headquartered parties. A self-hosted open-weight Chinese model sidesteps API data-residency worries but raises a different question your security and legal teams must answer.

The practical result: model choice now sits on three axes at once: capability, cost, and regulatory exposure. The table below shows how the main deployment options compare.

Deployment option Primary regulatory exposure Best-fit enterprise context
US frontier model via US cloud API EU AI Act transparency/high-risk duties; data residency Regulated workloads needing audit trails and a clear vendor of record
Open-weight Western model, self-hosted Conformity and documentation duties shift to you as deployer Sovereignty-sensitive data; teams with MLOps capacity
Chinese open-weight model, self-hosted Vendor-origin scrutiny; security review of weights and supply chain Cost-sensitive, lower-risk internal workloads after security sign-off
Chinese model via vendor-hosted API Data-transfer and "knowledge"-standard risk; DPDP/GDPR Generally avoid for regulated or personal-data workloads
Controlled chips deployed cross-border Direct EAR exposure; January 2026 certifications Only with export-control counsel and documented end-use checks

The China open-weight question, with numbers

The commercial pressure here is real and growing. Chinese open-weight models moved from roughly 1% to roughly 30% of tokens routed through OpenRouter, the largest neutral LLM router (a developer-traffic indicator, not global usage — first-party ChatGPT/Gemini traffic is far larger), with weekly peaks near 46% by mid-2026. Chinese labs have concentrated on small-to-mid-sized open-weight models, released free of charge, that undercut US frontier labs at the low end. The comparison briefers at AEI used was the auto market: most of the world wants a Corolla, not a Ferrari, and for a large share of desk work a 14-to-80-billion-parameter model running on local hardware is good enough.

For an enterprise, "good enough and free" is a strong pull. The catch is that free weights are not free of diligence. Two questions decide whether a Chinese open-weight model is usable: can you run it entirely on infrastructure you control, with no data leaving for a vendor-hosted endpoint, and has your security team reviewed the weights and provenance the way they would any third-party binary. If the answer to both is yes, a self-hosted open-weight model for a low-risk internal workload is a defensible engineering choice. If the workload touches personal data or sits in a regulated process, the calculus tightens fast, and a vendor-hosted Chinese API is the option most teams should rule out.

The real cost of switching is rarely the model. It is the migration, the eval rebuild, and the governance paperwork that follows.

The EU AI Act timeline collides with the 2026 buying cycle

If you serve EU users, export controls are only half the regulatory picture. The EU AI Act entered into force on 1 August 2024 and applies in stages. Prohibited practices and AI literacy duties applied from 2 February 2025. Obligations for general-purpose AI (GPAI) models applied from 2 August 2025. The bulk of the Act, including transparency rules under Article 50, becomes applicable on 2 August 2026.

The timeline then shifted. On 7 May 2026 the Council, Parliament, and Commission reached a provisional agreement on a "Digital Omnibus" that defers parts of the regime. Use-based high-risk obligations under Annex III moved from 2 August 2026 to 2 December 2027, product-embedded high-risk duties under Annex I moved to 2 August 2028, and the deadline for national regulatory sandboxes moved to 2 August 2027. The agreement also added prohibitions, effective 2 December 2026, on AI systems that generate non-consensual intimate material and child sexual abuse material.

The enforcement teeth are sharp. Breaches of the most serious obligations can draw fines up to €35 million or 7% of annual worldwide turnover, whichever is higher. For model choice, the operative point is that the transparency duties for chatbots still arrive in August 2026, and AI-generated-content labelling lands on 2 December 2026. If your selected model and your application around it cannot produce the disclosures and documentation the Act expects, the model is not fit for an EU deployment, however well it benchmarks.

Milestone Date What it means for model selection
GPAI model obligations apply 2 August 2025 Vendor must provide technical documentation and training-data summaries you can rely on
Bulk of AI Act applies; chatbot transparency 2 August 2026 Your app must disclose AI interaction; pick models whose vendors support this
AI-generated content labelling 2 December 2026 Watermarking/labelling capability becomes a selection criterion
Annex III high-risk obligations (deferred) 2 December 2027 Extra runway for high-risk use cases; do not treat as an excuse to defer governance
Annex I product-embedded high-risk 2 August 2028 Relevant if your AI ships inside a regulated product

A model-selection process that survives an audit

Put the two regimes together and a workable process emerges. It does not slow procurement much, and it produces the paper trail both an EAR review and an EU conformity assessment expect.

  1. Classify the workload first. Decide whether the use case is high-risk under the EU AI Act and whether it processes personal data. This determines how much documentation and human oversight you need before you compare any models.
  1. Screen vendor and chip origin. Identify the model vendor's ultimate parent and the hardware and region your inference will run on. Check counterparties against the Entity List and the D:5 country group. Where controlled chips or cross-border deployment are involved, bring in export-control counsel before signing.
  1. Benchmark the shortlist that survives screening. Only now run your capability, latency, and cost-per-million-token evals, comparing the models that cleared steps 1 and 2.
  1. Document the decision. Record why you chose the model, what you checked, and which obligations you mapped. That record is what turns a defensible choice into a provable one.

This sequencing matters. Screening after benchmarking wastes effort on models you cannot use and, worse, builds momentum behind a choice your compliance team will later block. Our SEO and AI strategy work follows the same order, which we cover in our generative AI enterprise strategy guide and our 2026 SEO playbook.

India-specific considerations

Indian enterprises sit in a useful position. India is not a Country Group D:5 destination, so US-origin chips and Western models are generally available, and the major cloud regions in India give access to frontier models through compliant endpoints. The constraint that bites for most Indian buyers is data protection, not export licensing.

The Digital Personal Data Protection Act 2023 governs how personal data is processed, and its rules shape where and how you can run inference on Indian users' data. For model choice, this means a vendor-hosted endpoint that moves personal data to an uncontrolled jurisdiction needs the same scrutiny an EU deployer would apply under the GDPR. A self-hosted open-weight model inside an Indian data centre can simplify data-residency questions, at the cost of the MLOps burden of running it. Costs in India for managed inference and private deployment typically run in the ₹40,000 to ₹4,00,000 per month range depending on model size and traffic, against acquisition economics where, globally, 1,700 NVIDIA H100-equivalent chips carry roughly a $42.5 million price tag. For most Indian enterprises, renting compliant inference beats owning controlled hardware. We discuss the wider discovery shift in our AEO, GEO and SEO guide.

How eCorpIT can help

eCorpIT is a CMMI Level 5 and MSME-certified, senior-led engineering organisation in Gurugram that builds and deploys enterprise AI systems across global and Indian markets. We help CTOs and compliance teams run the model-selection process above: classifying workloads, screening vendor and chip origin, benchmarking the shortlist, and producing documentation that holds up under an EU conformity assessment or an export-control review. We design applications aligned with EU AI Act and DPDP requirements. To scope a model-selection and governance review, contact our team.

FAQ

References

  1. Department of Commerce announces rescission of the AI Diffusion Rule, BIS press release (May 2025)
  1. Administration policies on advanced AI chips codified, Mayer Brown (January 2026)
  1. Managing export control risks in the AI chip ecosystem, Morrison Foerster (February 2026)
  1. AI technology export enforcement: signals companies cannot miss, Alvarez & Marsal (April 2026)
  1. BIS rescinds AI Diffusion Rule, issues enforcement guidance, Freshfields (May 2025)
  1. BIS issues long-awaited export controls on AI, WilmerHale (February 2025)
  1. Strengthening export controls, American Enterprise Institute (April 2026)
  1. Understanding the AI Diffusion Framework, RAND (January 2026)
  1. Managing export controls compliance across advanced technology sectors, Kharon (February 2026)
  1. AI Act overview, European Commission digital strategy
  1. EU AI Act update: timeline relief and new prohibitions, Global Policy Watch / Covington (May 2026)
  1. AI Act update: EU resolves to change rules and extend deadlines, Latham & Watkins (May 2026)
  1. AI implementation timeline, EU Artificial Intelligence Act portal

_Last updated: 22 June 2026._

Frequently asked

Quick answers.

01 Did the US ban exporting AI models in 2026?
No. BIS rescinded the AI Diffusion Rule on 13 May 2025, which removed ECCN 4E091, the planned control on advanced model weights. The January 2026 final rule loosened some chip exports to case-by-case review. The EAR "knowledge" standard, Entity List, and enforcement remain fully in force, so diligence is still required.
02 Can my enterprise legally run a Chinese open-weight model?
Often yes for low-risk internal workloads, after diligence. Run it entirely on infrastructure you control, with no personal data leaving for a vendor-hosted endpoint, and have your security team review the weights and provenance. For workloads touching personal data or regulated processes, a vendor-hosted Chinese API is the option most teams should rule out.
03 What are the EU AI Act penalties for a wrong model choice?
Breaches of the most serious obligations can draw fines up to €35 million or 7% of annual worldwide turnover, whichever is higher. For model selection, the practical risk is that chatbot transparency duties apply from 2 August 2026 and content labelling from 2 December 2026, so a model that cannot support required disclosures is unfit for EU deployment.
04 Why does chip export policy affect which model API I choose?
Because the controls flow downstream. The January 2026 rule names cloud and colocation providers offering controlled compute, and the EAR operates on vendor ownership and end-use, not just server location. If your inference runs on controlled hardware or your model vendor's parent sits in a restricted destination, that exposure becomes part of your model decision.
05 How big is China's share of AI usage now?
Chinese open-weight models moved from roughly 1% to roughly 30% of tokens routed through OpenRouter, the largest neutral LLM router (a developer-traffic indicator, not global usage — first-party ChatGPT/Gemini traffic is far larger), with weekly peaks near 46% by mid-2026. Chinese labs focused on small-to-mid-sized open-weight models released free of charge, which undercut US frontier labs for routine workloads where a 14-to-80-billion-parameter model is sufficient.
06 Does the EU AI Act timeline give me more time in 2026?
Partly. The 7 May 2026 Digital Omnibus agreement deferred use-based high-risk obligations under Annex III from 2 August 2026 to 2 December 2027, and product-embedded high-risk duties to 2 August 2028. But chatbot transparency still applies from 2 August 2026 and content labelling from 2 December 2026, so core selection criteria arrive on the original schedule.
07 What should Indian enterprises weigh most under DPDP?
Data protection more than export licensing. India is not a restricted destination, so Western models and US-origin chips are generally available. The Digital Personal Data Protection Act 2023 governs how personal data is processed, so a vendor-hosted endpoint moving Indian personal data abroad needs scrutiny. Self-hosting inside an Indian data centre can simplify residency at a higher MLOps cost.
08 What is the single biggest mistake in model selection right now?
Benchmarking before screening. Teams compare capability and cost first, build momentum behind a favourite, then discover compliance blocks it. Classify the workload and screen vendor and chip origin against the Entity List and country groups first, then benchmark only the models that survive. Document each step so a reviewer can follow the decision.

About the author

Manu Shukla

Founder & Director

Founder of eCorpIT. Hands-on engineer leading senior-only delivery for AI apps, custom software, and cloud systems for global clients.

Subscribe

One engineering note a week. No fluff, no spam.

Senior-architect playbooks on AI agents, mobile apps, cloud, security, data, and marketing — delivered every Wednesday.

Past the reading

Read enough. Let's build something.

A senior architect responds in 24 working hours with scope, indicative cost, and a timeline. NDA before any technical conversation.